KVM Vulnerability in Linux Kernel Impacting Arm64 Architecture
CVE-2026-64555
What is CVE-2026-64555?
A vulnerability has been identified in the Linux kernel's KVM component that affects the arm64 architecture. Specifically, the issue arises in the kvm_hyp_handle_mops() function, where it incorrectly resets the single-step state machine during MOPS exceptions. This defect hinders the correct restoration of SPSR_EL2 by failing to translate the synthetic state value produced by vcpu_cpsr() before writing back to hardware. This oversight could allow for improper state handling during nested virtualization scenarios. The resolution involves direct modification to SPSR_EL2, thereby avoiding the complications associated with synthetic states and ensuring accurate resynchronization upon subsequent transitions back to KVM.
Affected Version(s)
Linux 2de451a329cf662beeba71f63c7f83ee24ca6642 < 10a568010e827108d149779908850afaec898846
Linux 2de451a329cf662beeba71f63c7f83ee24ca6642 < 884b44256041ec6b2dcbe8e6a67384d26145cba1
Linux 2de451a329cf662beeba71f63c7f83ee24ca6642